Older, all-users-or-nobody controls that once governed which multifactor authentication and self-service password reset methods were allowed. From 30 September 2025 methods can no longer be configured there, as that role has passed to the Authentication methods policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Legacy MFA and SSPR policies in context, with comparison tables and the common traps.
Terms in this definition
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- SSPR
Allows users to unlock or reset their own passwords with methods they have registered. It can apply to All users, None, or Selected (a single group, with nesting supported).
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Authentication methods policy
Tenant-level Microsoft Entra policy that switches on each sign-in method, such as FIDO2, Authenticator, certificate-based authentication, TAP or SMS, for chosen users or groups.